Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Abracadabra Suffers Third DeFi Exploit As Hackers Drain $1.7 million

Abracadabra Suffers Third DeFi Exploit As Hackers Drain $1.7 million

BeInCryptoBeInCrypto2025/10/05 07:00
By:Oluwapelumi Adejumo

Abracadabra has suffered its third major breach in two years, reigniting scrutiny over the project’s code security and DeFi risk controls.

DeFi project Abracadabra has suffered a fresh exploit that drained about $1.7 million from its platform.

Blockchain security firm Go Security flagged the breach on October 4 and confirmed that attackers had already laundered about 51 ETH through Tornado Cash. At the time of reporting, the attacker’s wallet (identified as 0x1AaaDe) still held around 344 ETH, worth approximately $1.55 million.

How Abracadabra Was Exploited for the Third Time

Security researcher Weilin Li verified the exploit and explained that the attacker manipulated Abracadabra’s smart contract variables to bypass a solvency check.

This allowed them to borrow assets beyond the intended limit, prompting Abracadabra’s team to pause all contracts to prevent further losses.

Another blockchain audit firm, Phalcon, traced the root cause to a faulty logic sequence in the platform’s cook function. This is a mechanism that lets users execute several predefined actions in one transaction.

.@MIM_Spell was attacked hours ago, resulting in a loss of ~$1.7M. The root cause stems from the flawed implementation logic of the cook function, which allows users to execute multiple predefined operations in a single transaction. Specifically, the actions share a common… pic.twitter.com/4tQzkRbwcT

— BlockSec Phalcon (@Phalcon_xyz) October 4, 2025

According to the firm, the attacker carried out two operations that overrode key safeguards.

The first, known as action 5, initiated a borrowing process that was supposed to pass solvency checks. The second, called action 0, acted as an empty update function that rewrote the check flag and skipped the final validation step.

The attacker drained more than 1.79 million MIM tokens by repeating this pattern across six different addresses.

As of press time, Abracadabra has yet to comment publicly on the incident. Notably, the project’s official X account has remained silent since early September.

However, Go Security reported that the Abracadabra team confirmed on Discord that it would use DAO reserve funds to repurchase the affected MIM supply.

🚨 GoPlus Security Alert: The lending and stablecoin platform Abracadabra ( $SPELL ) appears to have been attacked again, with losses of approximately $1.77 million. Its official Twitter account @MIM_Spell has not been updated since September 9.Attacker Address:… pic.twitter.com/IjECKsOCWX

— GoPlus Security 🚦 (@GoPlusSecurity) October 5, 2025

Meanwhile, if verified, the latest incident would mark the third exploit against Abracadabra in under two years.

In January 2024, the platform lost $6.49 million in a hack that briefly depegged the MIM stablecoin from the US dollar. A second exploit in March 2025 drained another $13 million from its cauldron contracts, after which the team offered the hacker a 20% bounty.

The recurrence of such breaches raises renewed questions about the security of the DeFi protocol and the sustainability of its cross-chain lending architectures.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitcoin Updates: Crypto Market Faces Collapse as $217M in Leveraged Positions Are Liquidated

- A top Bitcoin whale with a "100% win rate" suffered its first loss, liquidating a $250M BTC long position at $12.68M after 24 hours. - The liquidation occurred amid a $217M global crypto crash, with Bitcoin falling below $113K and Ethereum under $4K due to leveraged trading cascades. - Geopolitical shifts (U.S.-China tensions easing) and a 97.8% chance of Fed rate cuts created conflicting market pressures, while other whales added leveraged ETH positions. - Analysts warn of leveraged position fragility,

Bitget-RWA2025/10/29 00:24
Bitcoin Updates: Crypto Market Faces Collapse as $217M in Leveraged Positions Are Liquidated

Bitcoin News Update: Undefeated Crypto Whale Faces Initial Setback, Highlighting Dangers of Leverage in Unstable Markets

- A "100% win rate" crypto whale suffered its first loss, liquidating a $2.5B BTC long at a $12.68M loss amid market volatility. - The whale now holds 10x leveraged ETH and SOL positions, while other whales scale BTC/ETH longs or open large ETH shorts via 25x leverage. - 24-hour price swings erased $600M in leveraged positions, with Bitcoin's long/short ratio stabilizing but "fragile sentiment" persisting. - Altcoin whales show divergent strategies, including a HYPE insider boosting 5x leveraged longs desp

Bitget-RWA2025/10/29 00:24
Bitcoin News Update: Undefeated Crypto Whale Faces Initial Setback, Highlighting Dangers of Leverage in Unstable Markets

Ethereum News Update: Individual Investors and Large Holders Face Off While Meme Coins Tackle a Turbulent 2025 Surge

- Meme coin market surges in 2025 as SPX6900 and Pudgy Penguins (PENGU) attract retail/institutional investors amid $1 price thresholds. - SPX6900 rose 13.61% with $42M volume growth, but whale selling risks $1.06 pullback despite strong derivatives activity. - Pudgy Penguins accumulates 2.8M tokens near $0.02 support, balancing NFT sales declines with Ethereum's rebound and holder retention. - MoonBull's absence from analyses highlights meme coin speculation, contrasting SPX6900/PENGU's on-chain clarity a

Bitget-RWA2025/10/29 00:08
Ethereum News Update: Individual Investors and Large Holders Face Off While Meme Coins Tackle a Turbulent 2025 Surge

MetaMask’s $30 Million Reward Program Faces Off Against Bittam’s Bold Incentive Offers

- MetaMask launches $30M rewards program with tiered benefits for trading, referrals, and cross-chain activities to boost user engagement. - Competes with Bittam's $3,000 new user bonuses and 200× leverage, focusing on retention through gamified points and exclusive perks. - Expands multichain support for EVM, Solana, and Bitcoin in MetaMask Mobile 7.57, integrating Linea's Layer 2 for fee discounts and token allocations. - Potential "MASK" token speculation rises as Polymarket odds hit 35% for 2025 launch

Bitget-RWA2025/10/29 00:08
MetaMask’s $30 Million Reward Program Faces Off Against Bittam’s Bold Incentive Offers